Radif

Security at Radif

Law firms trust Radif with sensitive financial workflows, so security isn't a feature we added; it's how the platform is built. Here is exactly how your data is protected.

Encryption everywhere
Your data is encrypted in transit and at rest using industry-standard strong encryption. There is no unencrypted path to your information, from your browser through to storage and backups.
Data stored in Canada
Your firm's data (database, documents and backups) is stored encrypted in Canada on managed, enterprise-grade cloud infrastructure. Like most modern services we rely on a small number of specialist providers (application delivery, email, payments); a full subprocessor list is available on request. Other regional arrangements are not part of the standard service and require a feasibility review before Radif makes a commitment.
Strict isolation between firms
Every record belongs to exactly one firm, and separation between firms is applied at the data layer on every request, not only in the application. Radif is designed so that one firm cannot read or change another firm's data.
Role-based access control
Access is governed by granular, role-based permissions that are enforced on the server, not merely hidden in the interface. Each firm decides who can submit, approve, work the accounting queue, and administer the workspace.
Private documents
Uploaded documents are stored privately and access-controlled, available only to authorized members of your firm and delivered through short-lived, expiring links.
Tamper-resistant audit trail
Every meaningful action on a request, from submission through approval to completion, is recorded with the responsible user and a timestamp in an audit trail that cannot be edited or deleted.
Secure authentication
Sign-in uses securely hashed credentials and email verification, with short-lived sessions that are refreshed automatically and can be revoked at any time. Disabling an account removes its access immediately.
Resilience and recovery
Radif runs on managed, redundant infrastructure. We do not currently publish a backup cadence or recovery-time guarantee; those commitments will be made only after the active infrastructure tier and a completed restore test support them.
Privacy commitment
Customer Data remains under your firm's control and is processed under contract and documented instructions. We do not sell it or use it to train shared AI models. Approved service providers receive only what is needed under contractual safeguards. Export and deletion follow the applicable contract, legal holds and documented retention process.

A maturing security program

Security is an ongoing commitment, and we continue to invest in our program as we grow with our customers. Prospective and current firms evaluating Radif can request more detail, including our approach to access controls, monitoring, and independent review, and we are glad to complete security questionnaires under a mutual NDA.

Questions about security or privacy? We'll answer them directly. Contact us any time. Radif is a workflow tool and not legal or accounting advice; each firm remains responsible for its own compliance.